Bug #77697 [Opn->Csd]: Crash on Big_Endian platform

From: Date: Fri, 15 Mar 2019 08:58:52 +0000
Subject: Bug #77697 [Opn->Csd]: Crash on Big_Endian platform
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219971@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77697&edit=1 ID: 77697 Updated by: laruence@php.net Reported by: samding at ca dot ibm dot com Summary: Crash on Big_Endian platform -Status: Open +Status: Closed Type: Bug Package: PHAR related Operating System: Linux PHP Version: 7.3.2 Block user comment: N Private report: N New Comment: Automatic comment on behalf of laruence@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=b41959089313d7397c936a885e9d1ca84e0f93f8 Log: Fixed bug #77697 (Crash on Big_Endian platform) Previous Comments: ------------------------------------------------------------------------ [2019-03-05 15:14:06] samding at ca dot ibm dot com Description: ------------ Test case: ext/phar/tests/phar_setsignaturealgo2.phpt has a core dump on Big-Endian platform. The Problem code is in "ext/phar/util.c": 1880 1881 if (!EVP_SignFinal (md_ctx, sigbuf,(unsigned int *)&siglen, key)) { 1882 efree(sigbuf); 1883 if (error) { 1884 spprintf(error, 0, "unable to write phar \"%s\" with requested openssl signature", phar->fname); 1885 } 1886 return FAILURE; 1887 } 1888 1889 sigbuf[siglen] = '\0'; // siglen is out of boundary, leads to a core dump 1890 EVP_MD_CTX_destroy(md_ctx); Debugger shows: (gdb) p siglen $1 = 549755814016 The reason is that "siglen" is defined as "size_t" (unsigned long), but in line 1881, when calling "EVP_SignFinal", it is cast-ed to "unsigned int" by pointer, which means to take the first 4 bytes in passing to "EVP_SignFinal". This is not a problem on Little_Endian platform, but has an issue on Big_endian platform, and caused the returned "siglen" in a large value. One of the solution is to define "siglen" as "unsigned int" instead of "size_t". Test script: --------------- ./sapi/cli/php run-tests.php -P ext/phar/tests/phar_setsignaturealgo2.phpt Expected result: ---------------- "siglen" should be returned as an index value. Actual result: -------------- (gdb) p siglen $1 = 549755814016 // wrong index value ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77697&edit=1

« previous php.bugs (#219971) next »